BGP Blackholing · RTBH

Stop attacks before they hit your line.

Real BGP blackholing for single-router networks. Works with any router that speaks BGP and a free private ASN you generate yourself — live in minutes.

$59/mo

7-day free trial • Auto-approved, no waiting on a human • Cancel anytime

Start Free Trial How It Works

Live BGP Blackhole Feed

Real-time API (2,000 req/day) of active threats, delivered as BGP routes your own router injects into its own table.

Encrypted Tunnel + Your Own BGP Session

GRE or WireGuard tunnel to a SATIS BGP PoP (Buffalo or Dallas), one session, one severity threshold you control.

Private ASN, No Multihoming

A free private ASN (64512–65534) and a router that speaks BGP is enough. No transit diversity, no LOA paperwork.

Auto-Approved

No admin review queue. Request a session, get your config, be live — typically minutes, not days.

How It Works

From signup to live blackholing in one sitting

1

Start Your Free Trial

Sign up, pick Shield. Card required for the trial, nothing charged for 7 days.

2

Request Your BGP Session

From the portal, request peering — auto-approved instantly, no waiting on a human to review it.

3

Download Your Config

A WireGuard config plus a copy-paste BGP peer block for your router's OS — Cisco IOS/IOS-XE, Juniper JunOS, OpenWrt, pfSense/OPNsense, VyOS, OpenBSD, or Linux+BIRD/FRR.

4

Traffic Gets Dropped Upstream

Once peered, malicious IPs above your chosen severity threshold get blackholed — dropped before they reach your line, not after.

What You Actually Need

  • A router that speaks BGP — from Cisco IOS/IOS-XE and Juniper JunOS to OpenWrt, pfSense/OPNsense, VyOS, OpenBSD, or Linux running BIRD or FRR. Homelab or enterprise, if it does BGP, it works.
  • A private ASN (64512–65534) — free, no RIR paperwork, generate one yourself in seconds
  • That's it — one router, one ASN, and you're peering

Questions

What is RTBH / BGP blackholing, actually?

Remote-Triggered Black Hole routing: your router announces a more-specific route for a malicious source IP with a special community tag, telling upstream routers to silently drop traffic to/from it — before it ever reaches your line. It's the same mechanism large ISPs use to absorb DDoS traffic, applied to a single-router network.

Do I need to be multihomed to peer with SATIS?

No. A single router with a private ASN and a GRE or WireGuard tunnel to a SATIS BGP PoP is enough. Multihoming and public ASNs matter for announcing your own routes to the wider internet — they're not required just to receive and act on our blackhole feed.

What happens after the 7-day trial?

Your card is charged $59 for the first month unless you cancel first, self-service, from the portal — no phone call or support ticket needed.

How is this different from Professional or Enterprise?

Shield is purpose-built for RTBH: one BGP session, one GRE/WireGuard tunnel, focused entirely on blackholing. Need real-time SSE streaming or more sessions? Professional and Enterprise build on the same peering, with a 14-day trial on Professional. Upgrading from the portal takes one click whenever you're ready.

Stop the Next Attack Upstream

Auto-approved BGP blackholing, live in minutes.

Start Free Trial

$59/mo after trial • 7 days free • Cancel anytime, self-service